CVE-2025-14432
Poly Video - Sensitive Data Might Be Written to Log File
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
16 dez 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Produtos afetados
HP Inc · Polycom EagleEye IVHP Inc · Poly EagleEye CubeHP Inc · Poly G7500HP Inc · Poly Studio A2HP Inc · Poly Studio E60HP Inc · Poly Studio E70HP Inc · Poly Studio G62HP Inc · Poly Studio USBHP Inc · Poly Studio X30HP Inc · Poly Studio X32HP Inc · Poly Studio X50HP Inc · Poly Studio X52HP Inc · Poly Studio X70HP Inc · Poly Studio X72HP Inc · TC10HP Inc · TC8Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →